October 18, 2021
|
5 min read
Most proctoring platforms accumulate years of student identity data, session recordings, and behavioral information, and their privacy policies explicitly allow that data to be transferred in a business sale. This post examines the risk of data stockpiling, the 400,000-student breach that demonstrated what happens when that data is targeted, and how Integrity Advocate's data minimization approach eliminates the risk by not holding data that does not need to exist.

At the heart of genuine privacy protection is a concept that sounds straightforward: data minimization. If personal data is never collected in the first place, it cannot be leaked, hacked, or sold. It cannot be transferred to a buyer in an acquisition. It cannot appear on the dark web.
The problem is that data minimization runs directly against the financial incentives of most technology companies. User data increases company valuation. The more a platform collects and retains, the more it is worth to investors, acquirers, and advertisers. For proctoring companies specifically, years of student behavioral data, identity images, and session recordings represent a significant asset on the balance sheet.
That asset belongs to your learners. And most of them have no idea it is being accumulated.
A review of privacy policies from proctoring companies around the world reveals language like this:
"In the event we sell some or all of our assets, it is possible your personal data could be one of the assets transferred to the purchaser."
"We may disclose your personal information to third parties if we are involved in a merger, acquisition, or sale of any or all of our business and/or our assets to a third party."
These are not edge cases buried in fine print. They are standard provisions in proctoring company privacy policies. They mean that the identity images, session recordings, and behavioral data your learners submitted for the purpose of completing an assessment can be transferred to an entirely different organization without their knowledge or consent.
The volume of data retained and the length of time it is kept directly increases the likelihood that it will be used, intentionally or unintentionally, in ways that harm the individuals it belongs to.
Encryption certificates and security procedures are frequently cited as assurances. They are not guarantees. A well-known proctoring service was breached despite these assurances, resulting in years of data involving over 400,000 students being obtained illegally and shared on the dark web.
The lesson is not that security measures are useless. It is that the most effective security measure is not having the data to begin with. Why would anyone hack a system that holds nothing of value?
Data minimization is not a policy position. It is an architectural decision. It means building a platform that:
Integrity Advocate deletes session recordings and identity images within 24 hours of completion for sessions with no violations. Personal data is not included as a transferable asset in any business transaction. As a Canadian company operating outside US jurisdiction, the data available on the vast majority of users in the unlikely event of a compelled disclosure would be limited to a name and a facial image represented as a string of code.
Before selecting a proctoring provider, organizations should be able to answer these questions from the vendor's privacy policy and data processing documentation:
If the answers are not clearly documented, that is itself an answer.
{{post-cta}}
Find answers to the most commonly asked questions from our clients.
Data minimization means collecting only the personal information that is necessary for a specific purpose and deleting it when that purpose is fulfilled. For online proctoring, it means a platform should not retain session recordings, identity images, or behavioral data beyond the immediate assessment. Data that does not exist cannot be hacked, sold, or transferred without consent.
Many proctoring company privacy policies explicitly allow personal data to be transferred as an asset in a merger, acquisition, or sale. This means student identity images and session recordings could be transferred to an entirely different organization without student knowledge or consent. Integrity Advocate does not include personal data as a transferable asset under any circumstances.
Yes. A well-known proctoring service experienced a data breach that resulted in years of data involving over 400,000 students being obtained illegally and shared on the dark web. The breach occurred despite the company's use of standard encryption and security procedures, demonstrating that data retention itself is a risk factor regardless of security measures in place.
Privacy-first online proctoring collects only the data necessary to verify identity, monitor assessment integrity, and produce a defensible result. That includes confirming the right person is taking the exam, monitoring behavior during the session for potential violations, and ensuring every flag is reviewed by a trained human before any outcome is issued. What it does not include: device-level access, software installs, or data collected beyond the scope of the assessment.
The most important insight from COTS 2025 on this topic is that security and privacy are not in conflict when a system is designed correctly from the start. Privacy-first proctoring collects only what is necessary, retains data only as long as required, and applies human judgment rather than broad surveillance to every decision. Organizations that treat this as an either/or choice are working with the wrong framework. The right approach is one that upholds both principles simultaneously through intentional design.